A living risk register
Your list of cyber risks, kept current for the whole term. Each risk has an owner, a treatment and its current state. Your vendors' risks sit in the same register, next to the business risks they affect.
Risk management as a service (RMaaS) for boards
An annual risk assessment shows your board where risk stood on one day. On a retainer, we keep your risk register current: the running list of your cyber risks, each with an owner. From it your board gets a regular cyber posture pack, with colour-coded heat maps scored the same way each time, your vendors sorted into risk tiers, and the gaps your executives found when they rehearsed an incident.
What the retainer covers
RMaaS is one of our managed security and compliance services. It helps your leadership make risk decisions it can explain to a board, an auditor or a customer.
Your list of cyber risks, kept current for the whole term. Each risk has an owner, a treatment and its current state. Your vendors' risks sit in the same register, next to the business risks they affect.
The register condensed for directors, with heat maps: colour-coded grids that show where risk sits. Every risk that moved up or down a rating band comes with a reason. On the enterprise tier (around 40 to 50 dedicated hours a month), we also report to your board directly.
Your executives rehearse a ransomware or data breach scenario taken from your own register. You get the gaps it exposes, such as a decision nobody in the room had the authority to make, each logged in the register with an owner.
Want a security executive to keep the register and present it to your board? See vCISO services. Need audit evidence kept current too? GRC as a service runs the register and audit readiness as one program, and compliance as a service covers the evidence alone.
Snapshot or record
A heat map is a picture of a single day. On its own it tells your board little. Next to the previous one, scored the same way, it shows what moved. Change the scoring method and a risk turns red with nothing behind it. Here are the same board questions, put to each kind of report.
| What the board asks | Annual assessment | Register on retainer |
|---|---|---|
| Which risks moved since we last looked? | It cannot say; it has one date | Each move and the event behind it |
| Which accepted risks need a new decision? | Whatever the next assessment finds | Those past their review date, or hit by an event that calls for a new decision |
| Did the fixes we paid for lower the rating? | Target dates in a treatment plan | The rating each risk still carries after a fix (its residual rating) |
| Which vendor could hurt us most now? | The vendor list on the day of the assessment | Current tiers and changes since the last pack |
| Can we show oversight to an auditor? | One dated report | Dated packs and the decisions in them |
At GV.RM-06, NIST's Cybersecurity Framework (CSF) 2.0 describes a standard method for calculating, documenting, categorizing and prioritizing cybersecurity risks. The table above assumes that method is in place, so each pack is scored the same way as the one before it.
To see where you stand against the whole framework, see NIST CSF 2.0.
For what makes a register useful, and the frameworks behind its scores, see our risk management page.
Vendor risk tiers
See which suppliers sit behind the risks your board already watches, for as long as you work with them.
An onboarding questionnaire checks a vendor once, at the start. NIST's CSF 2.0 outcome GV.SC-07 describes something longer: supplier and third-party risks recorded, prioritized, assessed, responded to and monitored for the life of the relationship.
On the retainer, we sort your vendors into tiers by risk and evaluate the supply chain behind them, meaning their own suppliers.
Judging one vendor by the access it holds is covered on our third-party risk management page.
Executive tabletops
A tabletop exercise is a guided discussion: your executives talk through an incident scenario and make the calls it forces. It tests decisions, not technology. Each exercise starts in the register and ends back in it.
The scenario comes from risks the pack already ranks high, such as ransomware on a core system or theft of customer personal data.
CISA, the US Cybersecurity and Infrastructure Security Agency, publishes a vendor supply chain compromise tabletop manual dated August 2024. A ransomware or breach scenario can begin at a critical vendor, which tests your vendor tiers as well as your executives.
Each turn of the scenario forces a decision executives would face in a real incident. If nobody in the room holds the authority to make one, that missing authority is itself a gap.
Each gap the exercise exposes becomes a register entry with an owner. If your retainer includes incident escalation coordination, as the enterprise tier does, the escalation path you rehearse is the one we coordinate in a real incident. The tabletop is one of our Blue Team exercises; response teams rehearse the technical side in incident response drills and detection checks.
Vetting providers
Test each proposal against what your board will actually read.
The limits of our own retainer. We recommend, and only your leadership accepts a risk. We do not promise a percentage of risk removed. SecWiz is not a law firm, so legal advice is not part of the retainer.
FAQ
Board packs, vendors, tabletops and terms. For anything else, ask us directly.
Risk Management as a Service (RMaaS) is cyber risk management bought as a retainer rather than a one-off project. At SecWiz it covers a living risk register, board-ready cyber posture packs with risk heat maps, vendor risk tiering and supply-chain evaluation, and executive tabletop exercises for ransomware and data breach scenarios.
An annual assessment records risk as it stood while the assessor was looking, then stays fixed. RMaaS keeps the register current through the retainer, so each board pack reads against the one before. The board sees direction: which risks grew, which shrank after treatment, and which decisions came due. One report shows only position.
A posture pack is the risk register condensed for directors. It holds heat maps scored with the same method as the last pack, a reason for every risk that changed band, accepted risks due for review, current vendor tiers and open tabletop gaps. On the enterprise tier, the retainer also includes direct board-level reporting.
Yes. Active third-party risk management is part of the retainer. Vendors are sorted into risk tiers, supply-chain evaluation looks past them to their own suppliers, and the results sit in the same register as internal risks, so the board pack shows a vendor's weakness beside the business risk it affects.
It tests decisions, not technology. Executives work through a ransomware or data breach scenario drawn from their own risk register and make the calls a real incident forces: whether to take a system offline, what to tell customers and regulators, who has the authority to decide, and who speaks for the company while it happens.
SecWiz sets a 6-month minimum term and a 12-month default, because remediating risk takes time to show results. Continuous automated compliance monitoring comes with a mid-market / growth retainer of around 20 to 25 committed fractional executive hours a month. On an enterprise retainer, direct board-level reporting and incident escalation coordination are part of around 40 to 50 dedicated hours a month.
Let's talk
Send it however old it is, or tell us nobody has produced one. The conversation starts from that report. We reply within one working day.